Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 ca4ca4a7381e4b88…

MALICIOUS

Office (OOXML) / .XLSX

120.1 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: ff0a64d14ae1c391908fb437ae651876 SHA-1: 75f143e8970b75bdb66cac242637cb85ab8e769f SHA-256: ca4ca4a7381e4b88bcfc9f01a88f127f6e3628647f55d3c68164147a883977c0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros. The extracted macro content is heavily obfuscated and truncated, making it impossible to determine the exact payload or execution flow. However, the presence of these macros strongly suggests an intent to execute arbitrary commands.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
f4b70e46cb137baf3917ff24f7852453c835fb77be45425b4b9ea52afd1f130d
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 221232 bytes